pavlo-database-performance

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHPROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [PROMPT_INJECTION]: The main title in SKILL.md ('# Andy Pavlo Style Guide') contains a long sequence of non-printable Unicode characters. These characters encode binary data that translates into text instructions. This method is used to perform prompt injection by stealthily providing instructions to the AI agent that are invisible to the user, intended to bypass standard instruction oversight.
  • [OBFUSCATION]: The skill makes extensive use of Zero-Width Joiners (U+200D), Zero-Width Non-Joiners (U+200C), Zero-Width Spaces (U+200B), and Word Joiners (U+2060). These characters are used to obfuscate the presence of a hidden message within the visible text. This is a high-severity indicator of a deliberate attempt to hide logic or instructions from human review and standard security auditing tools.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:05 PM